CVE-2026-64360: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: hfs/hfsplus: zero-initialize buffer in hfs_bnode_read hfs_bnode_read() can return early without writing to the output buffer when is_bnode_offset_valid() fails or when check_and_correct_requested_ length() corrects the length to zero. Callers such as hfs_bnode_read_ u16() and hfs_bnode_read_u8() pass stack-allocated buffers and use the result unconditionally, leading to KMSAN uninit-value reports. Rather than initializing at each individual call site, zero the buffer at the start of hfs_bnode_read() before any validation checks. This ensures all callers in both hfs and hfsplus get a deterministic zero value regardless of which early-return path is taken.

Affected products

  • Linux Linux Kernel: from 5.4.297, before 5.5 (fixed in 5.5); from 5.10.241, before 5.10.261 (fixed in 5.10.261); from 5.15.190, before 5.15.212 (fixed in 5.15.212); from 6.1.149, before 6.1.178 (fixed in 6.1.178); from 6.6.103, before 6.6.145 (fixed in 6.6.145); from 6.12.43, before 6.12.96 (fixed in 6.12.96); …

Published 2026-07-25. Last modified 2026-09-04.